Custom CA Certificate Support
Snyk API & Web now lets you upload your organization's internal Certificate Authority (CA), so the certificates it issues are trusted the same way as publicly issued certificates.
What's new
Many enterprises operate their own internal CA to issue certificates for both internal tools and internet-facing applications. Although these certificates aren't signed by a public CA, they should still be included in scans to prevent false positives.
What we're delivering
A method for uploading your Root CA. Each scan of every target then verifies certificates against your CA and the public trust store.
This increases scan accuracy, reduces the overhead of documenting risk acceptance for each affected target, and boosts the overall precision of each scan based on your specific needs and requirements.